committee-security-response icon indicating copy to clipboard operation
committee-security-response copied to clipboard

Document guide to interpreting CVSS for Kubernetes

Open tallclair opened this issue 3 years ago • 6 comments
trafficstars

It's not always clear how CVSS maps to Kubernetes. To help ensure consistency and reduce decision fatigue, we should document how we interpret and use various adjustments to rate vulnerabilities.

tallclair avatar Feb 05 '22 01:02 tallclair

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue or PR as fresh with /remove-lifecycle stale
  • Mark this issue or PR as rotten with /lifecycle rotten
  • Close this issue or PR with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot avatar May 06 '22 02:05 k8s-triage-robot

/triage accepted /lifecycle frozen

tabbysable avatar May 06 '22 03:05 tabbysable

I would scope this not at a "Kubernetes" system level - but to each "component" of K8s - ie this should probably be tightly coordinated (if not coupled) to the ongoing SBOM efforts

of course there could be an aggregate roll up of CVSS scores into a single score from those component-scoped scores

sunstonesecure-robert avatar Oct 20 '22 16:10 sunstonesecure-robert

@bjornsen is working on this

tallclair avatar Jan 05 '23 18:01 tallclair

Here's a document I put together with scoring thoughts. Please have a read and comment.

bjornsen avatar Jan 30 '23 17:01 bjornsen

This issue has not been updated in over 1 year, and should be re-triaged.

You can:

  • Confirm that this issue is still relevant with /triage accepted (org members only)
  • Close this issue with /close

For more details on the triage process, see https://www.kubernetes.dev/docs/guide/issue-triage/

/remove-triage accepted

k8s-triage-robot avatar Jan 30 '24 17:01 k8s-triage-robot